Is "@nx/js" on n8n Safe to Install?

GitHub Actions · n8n · v22.6.1

The JS plugin for Nx contains executors and generators that provide the best experience for developing JavaScript and TypeScript projects.

Risk Assessment

Analyzed
57.76
out of 100
MEDIUM

28 security findings detected across all analyzers

Severity Breakdown

0
Critical
0
High
2
Medium
26
Low
0
Info

Finding Categories

2
Obfuscation

About This Extension

The JS plugin for Nx contains executors and generators that provide the best experience for developing JavaScript and TypeScript projects.

Detailed Findings

28 total

Security Analysis Summary

Security Analysis Overview

@nx/js is a n8n extension published by GitHub Actions. Version 22.6.1 has been analyzed by the Risky Plugins security platform, receiving a risk score of 57.76/100 (MEDIUM risk) based on 28 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • Medium: 2 finding(s)
  • Low: 26 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

@nx/js is published by GitHub Actions on the n8n marketplace.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions